Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/drtimcooper/latlongtotimezone
Lat/long to timezone mapper in Java and Swift and C#. Does not require web services or data files.
The "lat/long to timezone polygon mapping" is hardcoded, and we hope this rarely changes, but the changes to offsets and daylight savings changeover dates etc. (which are more frequent) are taken care of by your system libraries and so these are automatically kept up-to-date. From time to time, someone updates the files with the latest timezone polygons, but these rarely change...I think the most recent change is the Crimean peninsular.
99% of people using this project just need the one file:
(Swift) https://github.com/drtimcooper/LatLongToTimezone/blob/master/Classes/TimezoneMapper.swift
(golang) https://github.com/zsefvlol/timezonemapper
# Podfile
use_frameworks!
pod 'LatLongToTimezone', '~> 1.1'
In the Podfile
directory, type:
$ pod install
Add this to Cartfile
github "drtimcooper/LatLongToTimezone" ~> 1.1
$ carthage update
Add https://github.com/drtimcooper/LatLongToTimezone
to your Swift packages in Xcode.
For Swift 2.3 and earlier, use version 1.0.4 of the Podspec. For Swift 3 to 4.1, use version 1.1.3 of the Podspec. For Swift 4.2 or later, use the latest version.
In your code, you can do
import LatLongToTimezone
let location = CLLocationCoordinate2D(latitude: 34, longitude: -122)
let timeZone = TimezoneMapper.latLngToTimezone(location)
TimezoneMapper
package com.skedgo.converter;
and replace it with your package (Don't forget the semicolon)Add in your Activity
:
val resultTimeZone = TimezoneMapper.latLngToTimezoneString(YOUR_LATITUDE, YOUR_LONGITUDE)
Log.i("", resultTimeZone)
Now you should see the TimeZone (open Logcat
)
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.